10 Jun 2010
The FBI has confirmed that it is investigating the iPad security breach that led to the collection of the email addresses of over 114,000 users.
Goatse Security said yesterday that it had exploited a flaw in AT&T's protocols that allowed the company to harvest data on 114,067 iPad 3G owners.
These included the White House chief of staff, New York mayor Michael Bloomberg and numerous senior people in the military, media and commerce sectors.
"The FBI is aware of these possible computer intrusions and has opened an investigation," FBI spokeswoman Katherine Schweit told The Wall Street Journal.
Schweit declined to comment on exactly what the agency is looking at, saying only that it is "very early in the investigation".
Meanwhile, researchers at Praetorian Security Group have published the full exploit code used in the attack. The flaw is a simple one, they said, which requires no actual hacking.
"An email address gets returned in the successful iterations (active ICCID) and parsed," said the company.
"There's no hack, no infiltration and no breach. Just a really poorly designed web application that returns email address when ICCID is passed to it. "
AT&T said in a statement that the function on its web site that allowed the emails to be collected had now been switched off.
"This issue was escalated to the highest levels of the company and was corrected by Tuesday. We have essentially turned off the feature that provided the email addresses," AT&T said in a statement.
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
Orange and Intel talk us through the ins and outs of their San Diego smartphone
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Project Manager - Credit Risk - Finance IT - Investment...
Infrastructure Configuration Manager/Analyst/Data Modeler...
Lead Perl Developer, Apache, SQL, Unix/Linux, Shell Scripting...
**Perl /Java Developer, Web/ JEE application servers...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
iPad or AT&T
So why is this being called an iPad security breach? Seems to me this has more to do with AT&T? I've chosen the simple option - buy the WIFI version. I don't have any security issues!
Posted by: Peter Scargill 14 Jun 2010